KOS-TL 使命软件檄文

MANIFESTO · 檄文

向软件使命时代进军

把软件绑回可检验的托付

关于建设中国新一代使命软件基础设施的檄文

知识操作系统是架构主张,不是已经交付的操作系统。使命软件工程学是体系主张,不是已经形成的学科。本文与同题专著《向软件使命时代进军》第13稿同一条脊骨:专著展开论证、数据与未解清单,本文只钉钉子。

客气已经用完了。软件行业擅长把事故写成个案,把结构问题写成运气不好,把“还在跑”写成“已经承担使命”。当一段程序开始调度电网、间隔列车、清算支付、决定剂量时,真正要问的不是它还不够快、还不够强。快和强已经发生了。缺的是绳子。

对手不是“还不够可信”。对手是假使命:看起来像服务,失败时不像失败。患者还在刷手机,列车还在跑,账本还在记,只是目的已经换了。没有可信,托付是空话;没有托付,可信是手段。使命的内涵包含可信。可信不是旁立的另一套最高概念。

没有可信,托付是空话;没有托付,可信是手段。

我们向软件使命时代进军,不是再喊一次产业口号,而是把软件绑回一件可检验的托付。

01一、命脉已经交给了一个陌生人

软件已经成为现代国家实际在用的操作系统。这句话不是隐喻。停电、停运、停诊、停清算,今天往往先是一段程序停了。Unix、C、数据库、编译器、云与大模型,把数学和工程变成了可执行的形式;金融、通信、电网、铁路、汽车、工厂、医院与城市治理,已经没有一套可以在软件之外独立运转的备用神经。人工智能还在把认知与行动写进这套神经。

我们不会把一座城市交给一位无法出示诊断依据、也无法被追问的医生,哪怕他看起来很忙、很贵、很新。软件就是这样一位陌生人:依赖已经停不下来,却很少有人能够读懂它的判断依据,更少能够在它说“继续”的时候强制它停下来。

Therac-25不是怀旧。它是一次信任转移的原型——从物理互锁转到程序保证,再从程序保证转到无人能够盘问。今天面对的不是一台加速器,而是成千上万个潜在的、隐藏的同类问题。

02二、十五万亿背后,缺的不是规模,是托付

2025年,中国软件和信息技术服务业实现软件业务收入15.48万亿元,同比增长13.2%;利润总额1.88万亿元;从业人员超过1,100万人。信息技术服务10.64万亿元,软件产品3.24万亿元,工业软件产品3,330亿元。以任何标准衡量,这都是一个庞大而充满活力的产业。

15.48 万亿2025 年软件业务收入 · 同比 +13.2%
1.39%基础软件 2,146 亿元
1.44%信息安全 2,235 亿元

成绩单里另有两个数字更值得看。基础软件收入2,146亿元,只占1.39%。信息安全产品和服务收入2,235亿元,只占1.44%。两者相加,不到全行业的百分之三。结构数字说明的不是产业不行,而是下一层还没有被建起来。

传统软件工程已经建立了人类工程史上最了不起的质量保障体系:语言、类型、编译、测试、静态与动态分析、审查、配置管理、安全、形式化验证、DevOps。本文对此抱有充分敬意。但它的核心预设是“正确性相对于规范定义”,而它把“规范本身是否正确”推到了自己的边界之外。一个系统可以完全做成被要求的系统,同时执行一件从未被托付的事。门禁被证明只认红色许可证,证明完全正确,要的却是授权——这是规范鸿沟。

十五万亿回答了规模。它还没有回答:在这十五万亿里,有多少软件能够出示行为论证,说明它仍在执行那一件被托付的事。

03三、对手不是“还不够可信”,是假使命

传统问题被写成:有没有缺陷。今天真正的问题已经远远超出缺陷。代码可以对,供应链可以列清单,模型可以出分,Agent可以执行。清单不是证据,声明不是使命。

假使命看起来像服务。它用“赋能”“智能”“为人民服务”这类无法被证伪的句子代替托付。为人民服务在这里不是横幅,而是一份有名字的名单:患者、乘客、调度员、存款人、士兵。名单之外的繁荣,可以是真生意,不能冒充这份托付。没有使命证据的软件,不能声称它服务于人民。

使命软件不是按行业划分的产品门类,也不是英文里的mission-critical。它是在特定托付关系中被五条同时绑住的软件:

MISSION-BOUND SOFTWARE

使命软件 ≡ 明示的托付 ∧ 明确的禁区 ∧ 绑在执行路径上 ∧ 可信(可检验的论证) ∧ 可被追究的人

少一条,对象就退回产品或愿景。可信在这里是认识论器官:论证可被别人拿去证伪。它不是可信计算的同义词。可信计算提供硬件信任根;可信赖性回答系统是否还在工作;可信性回答你怎么知道。三者互补。谁也不替代使命。使命在最上面。

04四、生成在加速,检查在掉队

美国国家标准与技术研究院给出的官方解释是:漏洞提交量在2020年至2025年间增长了263%。2025年它完成富化分析的漏洞接近42,000个,比历史上任何一年都多出45%。它跑得比以往任何时候都快。它还是输了。2026年4月15日,它所管理的国家漏洞数据库在制度上放弃了对全部漏洞做完整分析。信任的问题,不再只是该不该信任软件,而变成有没有能力判断软件是否仍在执行使命。

生成与验证不对称。大模型把生成成本压下去,把生成速度抬上去。这是一场生产力革命。它并不能自动补上检查。模型越强、生成越便宜,验证在总成本中的占比反而越高。人工智能既是工具,也是新对象:当一段代码由模型写出,当一个动作由Agent执行,流畅可以先于理解,行动可以先于纠正。

“让人工智能自己验收人工智能”在类型上走不通。统计判定回答看起来对不对;演绎判定回答能否重跑得到同一结果;制度判定回答谁有权决定对不对。无论把准确率提到多高,统计跨不到制度这一档。人要留在立法、划界、审判三个位置上。把最强的判断力放在监视屏幕前,是这一代最昂贵的一种浪费。

05五、供应链把可信计算基撑破了

现代软件几乎没有真正独立的程序。一个系统依赖几百、几千、数万个组件。可信计算基被供应链无限扩大。Verizon 2026年《Data Breach Investigations Report》显示,漏洞利用作为初始访问途径升至31%,十九年来首次超过凭证窃取。2025年同一系列报告显示,涉及第三方的泄露事件比例从15%上升到30%。必须更正一篇更早论述里的误用:48%是2026年报告中勒索软件占泄露事件的比例,不是第三方涉事比例。

IBM 2025年《数据泄露成本报告》给出全球单次平均成本444万美元、美国1,022万美元。444万是五年来首次下降,不能写成“代价一味增大”。下降的解释比绝对值更有价值:防御侧的人工智能有效;美国创新高则与监管罚款有关。同一份报告里,被攻陷的组织中97%没有部署人工智能访问控制。

软件错误的代价,从来不只是安全事件。故障、停机、金融错账、医疗错剂、供应链事故,都会进入同一本账。这不是软件企业自己的质量问题。这是整个数字经济的基础设施问题。

06六、理解世界并采取行动,仍可以执行未被写明的目的

Palantir常被写成“理解世界并采取行动”的样板。要争的是另一面。它的本体包含对象、关系、行动类型与动态安全,官方表述是数据、逻辑、行动与安全的四重整合。它不缺行动,也不缺权限。它真正缺少的是验证与证据:这个行动是对的吗?依据是什么?能否重建?规则之间是否一致?

没有验证与证据,理解世界仍可以执行未被写明的目的。下一代不能停在“这是什么、可以做什么、谁可以做、做了什么”。还必须回答:为什么允许;依据从哪里来;这个决定是否仍在那一件托付上;最终到底发生了什么,证据能否被别人拿去证伪。

材料可以写成:数据、知识、本体、规则、软件、人工智能、验证、执行、证据。绳子是另一件事。材料再齐,没有托付、禁区、绑定、可信与追究,仍可以执行更顺手的那一件事。

07七、做成系统,还是绑住目的

使命软件是对象。使命软件工程是使这个对象成立的工程。两者不能混。

核心只有一件:

CORE

核心 ≡ 明示的托付 ∧ 仍在执行这一件 ∧ 检查可被证伪

少了明示的托付,检查对着一张更顺手的目标函数,再严格也是假使命。少了仍在执行,定义停在纸上。少了可被证伪的检查,托付是声明,可信是空话。

本质区别不在多几份文档,也不在换一套节奏。以往软件工程做成系统;使命软件工程绑住目的。它不是软件工程学旁边另开的一门课,而是软件工程学在托付成为问题之后的下一次定向。它继承软件工程学的工程能力,不继承把交付当成成功。判据不换,底座只是更昂贵地交付假使命;底座不要,使命只是换了词的愿景。

四层必须分开立住。内涵:托付之工程,假使命为对手,可检查为成功,人在立法、划界、审判。它不是正确性2.0,不是安全换皮,不是可信计算,也不是知识操作系统。装置可以换,内涵不能换。方法论:原则先于步骤,步骤先于工具;禁区先于能力;定义、对齐、达成;生成与检查故障独立;强度与后果挂钩。生成覆盖广度,演绎覆盖深度。理论体系:对象是托付关系,问题是仍在执行这一件,判据是你怎么知道;加上规范鸿沟、生成与验证的不对称、信任转移、条件保证。可组合性仍是未解。工程体系:继承的底座,加上原则、对象、层次、环节与可重放。知识操作系统是装置的名字,用来让核心可计算,不是已经交货的操作系统。仓库里的原型可以检验若干机制,不能被当成规格已经实现的证据。

体系可以主张。学尚未形成。

08八、不是安全产业的细分,是准入条件

网络安全不能单独解决这件事。安全关注的是面对恶意时能否维持性质;可信性的大部分问题与恶意无关:错误的知识、冲突的规则、未经审议的默认、静默的行为漂移。Ken Thompson说过,你无法信任不是你亲手创造的代码。代码越来越由机器生成时,这句话变得更深:不仅不是亲手创造的,甚至它是否被理解,都无法确定。

大模型不会自动解决。传统软件工程也无法单独解决。需要的是新的综合:把知识与规则做成可计算的一等公民;让行动与轨迹可记录、可检查、可撤销;让证据在正常运行中自动产生;让可信性从芯片走到行动,而不是停在孤立节点上。

这不是再建设一个单独的“安全软件产业”,而是横切所有软件领域的一层:从可信芯片、基础软件、知识操作系统,到本体、使命人工智能、使命Agent、行业软件、认证与服务。分级与证据格式是定价、认证与交易的前提。使命Agent基础设施的时间窗口最紧。把构建溯源纳入信创的技术判据,是目前最具可操作性的制度动作。

以2025年15.48万亿元软件业务收入为基准,1%的渗透大约是1,548亿元,5%大约是7,742亿元。这是情景测算,不是市场预测。即使只成为整个软件产业中的一个小价值层,也足以形成千亿元乃至万亿元级空间。更有意义的不是切出一块收入,而是解锁已经发生、却尚未兑现的人工智能价值。使命创造的价值,可能远大于它捕获的收入。

09九、强国不是规模,是定义使命的权力

我们不能满足于成为软件的使用者。软件大国意味着规模。软件强国包含递进的几层:基础理论、核心基础软件、标准、生态、基础设施,以及下一代软件范式。前面几层是追赶。最后一层是跃迁。在既有范式内追赶困难,因为壁垒是生态锁定;在范式转换点上跃迁可能,因为新范式没有需要迁移的既有生态。使命软件构成真实的转换点——它改变了问题的定义。认识到转换点的存在,与在其中占据位置,是两件不同的事。

最有价值的是定义人工智能进入现实世界的使命机制。当人工智能从生成走向行动,决定它能被用到什么程度的不再只是能力,而是行动能否被信任。这套机制在全球都不成熟。中国的行业知识只能由中国自己形式化。定义权也是责任:一个不能被独立检验的标准,无论由谁定义,都是自相矛盾的。正确姿态不是抢占标准,而是做出更好的东西并让它可被检验。

中国已经拥有十五万亿元级软件产业、庞大的制造业、世界规模最大的产业应用场景之一、快速发展的人工智能、完整的软件产业链,以及1,100万软件从业者。这个规模既是优势也是约束:任何需要专家才能使用的方案,在这个规模上都无法推广;必须把其中最强的一部分,从虚假繁荣拨向工业与国防科技工业软件。缺少的不是基础。缺少的是把这些基础组织成下一代使命软件基础设施的战略能力,以及愿意在未解问题上工作很多年的人。

10十、这一代要回答的,与尚未解开的

回望软件史:Unix回答操作系统如何组织,C回答如何在接近机器的同时保持可移植,Lisp回答程序如何处理符号与自身,Web回答信息如何跨越边界,开源回答谁有权修改与检查,云与移动回答软件如何变成远程能力,Git回答分布式协作如何保持一致,LLVM回答编译基础设施如何被复用。大模型正在回答软件应当如何被生产。尚未被回答的,是这一次生产跃迁之后,验证与证据放在哪里。

这一代需要继续回答:如何让软件真正理解现实世界;如何定义、对齐、达成一件托付;如何把内涵、方法论、理论体系与工程体系分开立住,而不假装学科已经立住;如何让知识成为计算的一部分;如何让人工智能按使命使用知识;如何让Agent按使命采取行动;如何让复杂软件拥有可验证的行为;如何让每一个关键决策都能被解释、追踪和审计。它们目前都没有成熟的答案。这既是困难,也是值得投入的理由。

最应当避免的,是让人以为问题已经被解决。建模成本是整条路线最主要的实践风险,目前尚未被证明已解决。可组合性仍依赖工程纪律而非架构保证。表达力与可判定性存在理论限制。可能存在一类系统,其性能要求与完整使命论证根本不兼容。知识表示的标准化、人工智能边界的实际维持、证据保存与隐私的冲突,都还在。形式合规取代实质使命、被平台吸收而不形成独立产业、国际标准窗口关闭,同样可能发生。这些不是免责声明,而是这条路线的真实地形。一个知道自己边界的系统,比一个不知道自己边界的系统更可信。一条路线也是如此。

CODA结语:让软件从“能够运行”走向“承担使命”

软件不仅要能够运行,更必须承担使命。这句话听起来近乎常识。它目前还不是现实。

现阶段能够诚实争取的,不是让一切软件承担使命,而是三件更窄的事:让关键系统开始出示论证;让生成与验证不再朝相反方向跑;让行动进入现实世界时留下可检验的轨迹。机械的核对必须交给机器。人要回到只有人能站的位置——定义意图、设定边界、保有推翻机器结论的能力与证据。

驯服软件、驯服人工智能,是同一条缰绳。把它们做成可检验的使命,才谈得上真正为人民服务。其余的,留给实践去证伪或证实。

向软件使命时代进军。

MANIFESTO · 檄文

Advance into the Age of Mission-bound Software

Bind software back to an inspectable charge

A manifesto on building China’s next-generation mission-bound software infrastructure

A Knowledge Operating System is an architectural claim, not a shipped operating system. Mission-bound software engineering is a systems claim, not a formed discipline. This essay shares one spine with the monograph *Advance into the Age of Mission-bound Software*, draft 13: the book carries the argument, the data and the unsolved list; this text only drives the nails.

Courtesy is spent. The software trade is good at writing accidents as cases, structural problems as bad luck, and “it is still running” as “it already bears a mission.” When a program begins to dispatch a grid, space trains, clear payments or set a dose, the real question is not that it is not yet fast enough or strong enough. Speed and strength have already arrived. What is missing is the rope.

The opponent is not “not trustworthy enough.” The opponent is a false mission: it looks like service, and does not look like failure when it fails. The patient is still on a phone, the train is still moving, the ledger is still being written—only the purpose has already changed. Without trustworthiness, a charge is empty talk; without a charge, trustworthiness is a means. Mission contains trustworthiness. Trustworthiness is not another highest concept standing beside it.

Without trustworthiness, a charge is empty talk; without a charge, trustworthiness is a means.

To advance into the age of mission-bound software is not another industrial slogan. It is to bind software back to one inspectable charge.

01I. The vital systems have already been handed to a stranger

Software has become the operating system a modern state actually uses. That is not a metaphor. A blackout, a stoppage of trains, of clinics, of clearing, today often begins when a program stops. Unix, C, databases, compilers, the cloud and large models turned mathematics and engineering into executable form. Finance, communications, the grid, railways, cars, factories, hospitals and city government no longer have a spare nervous system that can run outside software. Artificial intelligence is still writing cognition and action into that nerve.

We would not hand a city to a doctor who cannot show the grounds of a diagnosis and cannot be questioned—however busy, expensive or new he looks. Software is that stranger: dependence can no longer be stopped, yet few can read its grounds, and still fewer can force it to halt when it says “continue.”

Therac-25 is not nostalgia. It is a prototype of a transfer of trust—from a physical interlock to a program’s guarantee, then from that guarantee to a place where no one can put a question. What we face now is not one accelerator, but thousands of potential, hidden cases of the same kind.

02II. Behind fifteen trillion, what is missing is not scale. It is the charge

In 2025 China’s software and information-technology services booked RMB 15.48 trillion in software business revenue, up 13.2%; profit RMB 1.88 trillion; more than 11 million people employed. IT services RMB 10.64 trillion; software products RMB 3.24 trillion; industrial software products RMB 333 billion. By any measure this is a large and living industry.

¥15.48 tn2025 software business revenue · +13.2% YoY
1.39%Foundational software · ¥214.6 bn
1.44%Information security · ¥223.5 bn

Two other figures on the same sheet matter more. Foundational software: RMB 214.6 billion, 1.39%. Information-security products and services: RMB 223.5 billion, 1.44%. Together, less than three percent of the whole. The structural numbers do not say the industry has failed. They say the next layer has not been built.

Classical software engineering has built the most formidable quality apparatus in the history of human engineering: languages, types, compilation, testing, static and dynamic analysis, review, configuration, security, formal verification, DevOps. This essay holds that in full respect. But its core premise is that correctness is defined relative to a specification, and it pushes “whether the specification itself is right” outside its own border. A system can be made exactly as required and still execute something that was never charged to it. A gate is proved to accept only a red permit—the proof is perfect—when what was wanted was authorization. That is the specification gap.

Fifteen trillion answers scale. It has not answered: of that fifteen trillion, how much software can produce an argument of behavior, showing that it is still executing the one thing it was charged to do.

03III. The opponent is not “not trustworthy enough.” It is a false mission

The old question was written: are there defects? Today’s real question has already gone far beyond defects. Code can be right, the supply chain can show a list, a model can post a score, an agent can execute. A list is not evidence. A declaration is not a mission.

A false mission looks like service. It replaces the charge with sentences that cannot be falsified—“empowerment,” “intelligence,” “serve the people.” Serve the people is not a banner here. It is a named list: patients, passengers, dispatchers, depositors, soldiers. Prosperity outside that list may be a real business. It cannot impersonate this charge. Software without evidence of mission cannot claim to serve the people.

Mission-bound software is not a product category cut by industry, nor *mission-critical* in English. It is software bound, in a particular relation of charge, by five things at once:

MISSION-BOUND SOFTWARE

Mission-bound software ≡ an explicit charge ∧ an explicit forbidden zone ∧ bound onto the path of execution ∧ trustworthiness (an inspectable argument) ∧ a person who can be held to account

Miss one, and the object falls back to a product or a vision. Trustworthiness here is an epistemological organ: an argument others can take away and try to falsify. It is not a synonym for trusted computing. Trusted computing supplies a hardware root of trust; dependability answers whether the system is still working; trustworthiness answers how you know. The three complement one another. None replaces mission. Mission sits on top.

04IV. Generation is accelerating. Inspection is falling behind

The U.S. National Institute of Standards and Technology’s official account is that vulnerability submissions grew 263% from 2020 to 2025. In 2025 it finished enriching nearly 42,000 vulnerabilities, 45% more than in any year in its history. It ran faster than it ever had. It still lost. On 15 April 2026 the National Vulnerability Database it runs abandoned, as a matter of policy, complete analysis of every vulnerability. The question of trust is no longer only whether software should be trusted. It is whether we still have the capacity to judge whether software is still executing its mission.

Generation and verification are asymmetric. Large models push the cost of generation down and the speed of generation up. That is a productivity revolution. It does not automatically supply inspection. The stronger the model, the cheaper the generation, the higher the share of verification in total cost. Artificial intelligence is both a tool and a new object: when a model writes the code, when an agent performs the act, fluency can precede understanding, and action can precede correction.

“Let AI accept AI” does not go through in type. Statistical judgment answers whether something looks right; deductive judgment answers whether a rerun yields the same result; institutional judgment answers who has the authority to decide that it is right. No accuracy, however high, lets statistics climb into the institutional tier. Persons must remain in three seats: legislation, boundary-drawing, judgment. To put the strongest judgment in front of a monitoring screen is this generation’s most expensive waste.

05V. The supply chain has stretched the trusted computing base until it burst

There is almost no truly independent program left. A system depends on hundreds, thousands, tens of thousands of components. The trusted computing base is enlarged without limit by the supply chain. Verizon’s 2026 *Data Breach Investigations Report* shows exploitation of vulnerabilities as an initial access path rising to 31%, overtaking stolen credentials for the first time in nineteen years. The 2025 report in the same series shows incidents involving third parties rising from 15% to 30%. An earlier essay must be corrected: 48% is the share of breaches involving ransomware in the 2026 report, not the share involving third parties.

IBM’s 2025 *Cost of a Data Breach Report* gives a global average of USD 4.44 million per incident, and USD 10.22 million in the United States. 4.44 million is the first fall in five years. It cannot be written as “the cost only grows.” The explanation of the fall is worth more than the absolute: AI on the defensive side works; the U.S. record high is tied to regulatory fines. In the same report, 97% of compromised organizations had not deployed AI access control.

The cost of software error was never only a security incident. Faults, downtime, a wrong financial entry, a wrong medical dose, a supply-chain accident, all enter the same ledger. This is not a quality problem for software firms alone. It is an infrastructure problem for the whole digital economy.

06VI. Understanding the world and taking action can still execute a purpose that was never written down

Palantir is often written as the specimen of “understand the world and take action.” The other face is what is to be contested. Its ontology contains objects, relations, action types and dynamic security; the official formula is a fourfold integration of data, logic, action and security. It does not lack action, nor permission. What it truly lacks is verification and evidence: was this action right? On what grounds? Can it be reconstructed? Are the rules consistent with one another?

Without verification and evidence, understanding the world can still execute a purpose that was never written down. The next generation cannot stop at “what is this, what can be done, who may do it, what was done.” It must still answer: why is it allowed; where did the ground come from; is this decision still on that one charge; what, in the end, happened, and can the evidence be taken away and falsified by someone else.

The materials can be written: data, knowledge, ontology, rules, software, AI, verification, execution, evidence. The rope is another thing. However complete the materials, without charge, forbidden zone, binding, trustworthiness and account, the system can still execute whichever purpose comes more readily to hand.

07VII. Make a system, or bind a purpose

Mission-bound software is the object. Mission-bound software engineering is the engineering that makes that object hold. The two must not be mixed.

The core is only one thing:

CORE

Core ≡ an explicit charge ∧ still executing this one thing ∧ inspection that can be falsified

Without an explicit charge, inspection faces a more convenient objective function; however strict, it is still a false mission. Without still-executing, the definition stays on paper. Without inspection that can be falsified, the charge is a declaration and trustworthiness is empty talk.

The essential distinction is not a few more documents, nor a change of cadence. Classical software engineering makes a system; mission-bound software engineering binds a purpose. It is not a course opened beside software engineering. It is software engineering’s next orientation, after the charge itself became the problem. It inherits the engineering capacity of software engineering. It does not inherit “delivery equals success.” If the criterion is not changed, the base only delivers a false mission at greater expense. If the base is refused, mission is only a vision that changed its words.

Four layers must be set up apart. Connotation: the engineering of a charge; false mission as opponent; inspectability as success; persons in legislation, boundary-drawing and judgment. It is not correctness 2.0, not security under a new skin, not trusted computing, and not a Knowledge Operating System. The apparatus can be changed. The connotation cannot. Method: principles before steps, steps before tools; the forbidden zone before capability; define, align, achieve; generation and inspection fail independently; intensity tied to consequence. Generation covers breadth; deduction covers depth. Theory: the object is a relation of charge; the problem is still executing this one thing; the criterion is how you know—plus the specification gap, the generation–verification asymmetry, the transfer of trust, conditional guarantee. Composability remains unsolved. Engineering system: the inherited base, plus principles, objects, layers, links and replay. A Knowledge Operating System is the name of the apparatus, used to make the core computable. It is not a shipped operating system. Prototypes in a repository can test some mechanisms. They cannot be taken as evidence that a specification has already been realized.

A system can be claimed. The discipline has not yet formed.

08VIII. Not a niche of the security industry. An entry condition

Cybersecurity cannot solve this alone. Security asks whether a property can be kept under malice; most problems of trustworthiness have nothing to do with malice: wrong knowledge, conflicting rules, undeliberated defaults, silent drift of behavior. Ken Thompson said you cannot trust code you did not create yourself. When code is increasingly generated by machines, the sentence goes deeper: not only was it not created by our hands; even whether it was understood cannot be determined.

Large models will not solve it by themselves. Classical software engineering cannot solve it alone. What is needed is a new synthesis: make knowledge and rules first-class computable citizens; make actions and traces recordable, inspectable, revocable; let evidence arise in ordinary running; let trustworthiness walk from chip to action, and not stop at an isolated node.

This is not another isolated “security-software industry.” It is a layer cut across every software domain: from trusted chips and foundational software and a Knowledge Operating System, to ontologies, mission-bound AI, mission-bound agents, industry software, certification and services. Grading and evidence formats are the premise of pricing, certification and trade. The time window for mission-bound agent infrastructure is the tightest. To bring build provenance into the technical criteria of Xinchuang is, for now, the most operable institutional move.

Taking 2025’s RMB 15.48 trillion of software business revenue as the base, 1% penetration is about RMB 154.8 billion; 5% about RMB 774.2 billion. This is a scenario calculation, not a market forecast. Even as a thin value layer inside the whole software industry, it is enough to form a space of hundreds of billions—even trillions—of yuan. What matters more than cutting out a slice of revenue is unlocking AI value that has already arrived and has not yet been cashed. The value a mission creates may far exceed the revenue it captures.

09IX. A strong country is not scale. It is the power to define a mission

We cannot be content to remain users of software. A large software country means scale. A strong software country contains successive layers: foundational theory, core systems software, standards, ecology, infrastructure, and the next software paradigm. The first layers are catch-up. The last is a leap. Catch-up inside an existing paradigm is hard, because the barrier is ecological lock-in; a leap at a point of paradigm change is possible, because the new paradigm has no existing ecology that must be migrated. Mission-bound software is a real point of change—it changes the definition of the problem. To recognize the point of change, and to occupy a place in it, are two different things.

What is most valuable is to define the mission mechanism by which AI enters the real world. When AI moves from generation to action, what decides how far it may be used is no longer capability alone, but whether the action can be trusted. That mechanism is immature everywhere. China’s industry knowledge can be formalized only by China. The power to define is also a duty: a standard that cannot be independently inspected, whoever defines it, contradicts itself. The right stance is not to seize a standard, but to make something better and let it be inspectable.

China already has a software industry on the order of fifteen trillion yuan, a vast manufacturing system, one of the world’s largest bodies of industrial application, fast-growing AI, a complete software chain, and 11 million software workers. That scale is both an advantage and a constraint: any scheme that only experts can use cannot spread at this scale; the strongest part of that corps must be turned from a false prosperity toward industrial and defense-industrial software. What is missing is not the base. What is missing is the strategic capacity to organize that base into next-generation mission-bound software infrastructure, and people willing to work for many years on problems still unsolved.

10X. What this generation must still answer, and what is not yet undone

Look back: Unix answered how an operating system should be organized; C, how to stay close to the machine and remain portable; Lisp, how a program treats symbols and itself; the Web, how information crosses a boundary; open source, who may change and who may inspect; cloud and mobile, how software becomes a remote capability; Git, how distributed collaboration stays consistent; LLVM, how compiler infrastructure is reused. Large models are answering how software should be produced. What has not been answered is where, after this leap in production, verification and evidence are to be placed.

This generation must still answer: how software can truly understand the real world; how to define, align and achieve a charge; how to set connotation, method, theory and engineering apart, without pretending the discipline already stands; how knowledge becomes part of computation; how AI uses knowledge under a mission; how an agent acts under a mission; how complex software can have verifiable behavior; how every critical decision can be explained, traced and audited. None of these yet has a mature answer. That is the difficulty, and the reason it is worth the work.

What must most be avoided is letting anyone think the problem is already solved. Modeling cost is the chief practical risk of the whole route; it has not been shown to be solved. Composability still depends on engineering discipline, not on an architectural guarantee. Expressiveness and decidability are theoretically constrained. There may be a class of systems whose performance requirements are simply incompatible with a complete mission argument. Standardization of knowledge representation, the actual holding of AI’s boundary, the conflict between keeping evidence and keeping privacy, all remain. Formal compliance replacing a real mission, absorption into a platform so that no independent industry forms, the closing of a window in international standards, can all still happen. These are not disclaimers. They are the real terrain of the route. A system that knows its own border is more trustworthy than one that does not. A route is the same.

CODACoda: from “it runs” to “it bears a mission”

Software must not only be able to run. It must bear a mission. The sentence sounds like common sense. It is not yet a fact.

What can be honestly sought at this stage is not that all software bear a mission, but three narrower things: that critical systems begin to produce arguments; that generation and verification stop running in opposite directions; that when an action enters the real world it leaves an inspectable trace. Mechanical checking must be given to machines. Persons must return to the seats only persons can occupy—defining intent, setting a boundary, keeping the capacity and the evidence to overturn a machine’s conclusion.

To tame software and to tame artificial intelligence is the same rein. Only when they are made into an inspectable mission can one speak of truly serving the people. The rest is left to practice, to falsify or to confirm.

Advance into the age of mission-bound software.